Skip to content

Conversation

rBangay
Copy link
Contributor

@rBangay rBangay commented Nov 27, 2024

What does this PR change?

Update peer dependency @guardian/cdk and use the package.json resolutions to force a patched version of cross-spawn

Should fix vulnerability reported by dependabot and snyk:

https://github.com/guardian/manage-frontend/security/dependabot/164
https://app.snyk.io/org/guardian-value/project/8acda083-6b55-431d-a2e0-a985b2349e78

…ncies and forcing a patched version by using the reolutions block in package.json
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant